HyperComments WordPress Plugin Missing Capability Check Vulnerability Allowing Privilege Escalation
Vulnerability
A vulnerability exists in the HyperComments plugin for WordPress, in all versions through 1.2.2, due to a missing capability check in the hc_request_handler function. This flaw allows unauthorized users to modify data arbitrarily, potentially leading to privilege escalation. Exploitation of this vulnerability could enable an attacker to change the default user role for registrations to administrator, thereby gaining administrative access on the affected WordPress site.
Impact
Exploitation of this vulnerability could allow an attacker to gain administrative privileges on a WordPress site by manipulating user roles through the WordPress options system.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
